diff --git a/.github/actions/add-item-to-project/action.yml b/.github/actions/add-item-to-project/action.yml index 4d114986..cea4e966 100644 --- a/.github/actions/add-item-to-project/action.yml +++ b/.github/actions/add-item-to-project/action.yml @@ -23,7 +23,7 @@ runs: using: composite steps: - name: Add item to project board - uses: actions/add-to-project@v1.0.2 + uses: actions/add-to-project@244f685bbc3b7adfa8466e08b698b5577571133e # v1.0.2 # If filtering is disabled, the condition is always true. # If filtering is enabled, then: # - For PRs, check that the PR either has the specified team in requested_team diff --git a/.github/actions/check-changelog/action.yml b/.github/actions/check-changelog/action.yml index c0c580f2..33a4bd7c 100644 --- a/.github/actions/check-changelog/action.yml +++ b/.github/actions/check-changelog/action.yml @@ -45,7 +45,7 @@ runs: - name: Check out target repository if: ${{ steps.label-check.outputs.skip_check != 'true' }} - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.repo }} ref: ${{ inputs.head-ref }} @@ -64,7 +64,7 @@ runs: - name: Checkout GitHub tools repository if: ${{ steps.label-check.outputs.skip_check != 'true' }} - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} @@ -78,7 +78,7 @@ runs: - name: Set up Node.js if: ${{ steps.label-check.outputs.skip_check != 'true' }} - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version-file: ./.github-tools/.nvmrc cache-dependency-path: ./.github-tools/yarn.lock diff --git a/.github/actions/check-skip-merge-queue/action.yml b/.github/actions/check-skip-merge-queue/action.yml index 30ed5698..27ead833 100644 --- a/.github/actions/check-skip-merge-queue/action.yml +++ b/.github/actions/check-skip-merge-queue/action.yml @@ -41,7 +41,7 @@ runs: - name: Get pull request details continue-on-error: true id: pr-details - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: HEAD_REF: ${{ inputs.head-ref }} with: @@ -85,7 +85,7 @@ runs: - name: Check if pull request is up-to-date with base branch continue-on-error: true id: up-to-date - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: BASE_REF: ${{ inputs.base-ref }} PR_BRANCH: ${{ steps.pr-details.outputs.pr-branch }} diff --git a/.github/actions/create-release-pr/action.yml b/.github/actions/create-release-pr/action.yml index 7d9c5dab..1c4ee2c2 100644 --- a/.github/actions/create-release-pr/action.yml +++ b/.github/actions/create-release-pr/action.yml @@ -62,7 +62,7 @@ runs: steps: # Step 1: Checkout invoking repository (metamask-mobile | metamask-extension ) - name: Checkout invoking repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: fetch-depth: 0 ref: ${{ inputs.checkout-base-branch }} @@ -70,7 +70,7 @@ runs: # Step 2: Checkout github-tools repository - name: Checkout github-tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} @@ -78,7 +78,7 @@ runs: # Step 3: Setup environment - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true @@ -151,7 +151,7 @@ runs: # Step 6: Upload commits.csv as artifact (if generated) - name: Upload commits.csv artifact if: ${{ hashFiles('commits.csv') != '' }} - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: commits-csv path: commits.csv diff --git a/.github/actions/flaky-test-report/action.yml b/.github/actions/flaky-test-report/action.yml index b907583a..fc79ad1a 100644 --- a/.github/actions/flaky-test-report/action.yml +++ b/.github/actions/flaky-test-report/action.yml @@ -27,14 +27,14 @@ runs: using: composite steps: - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} path: ./github-tools - name: Set up Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version-file: ./github-tools/.nvmrc cache-dependency-path: ./github-tools/yarn.lock diff --git a/.github/actions/get-release-timelines/action.yml b/.github/actions/get-release-timelines/action.yml index 679ca2de..d3d7c278 100644 --- a/.github/actions/get-release-timelines/action.yml +++ b/.github/actions/get-release-timelines/action.yml @@ -27,7 +27,7 @@ runs: using: composite steps: - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} @@ -45,7 +45,7 @@ runs: run: ./github-tools/.github/scripts/get-release-timelines.sh - name: Upload artifact release-timelines-${{ inputs.version }}.csv - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: release-timelines-${{ inputs.version }}.csv path: release-timelines-${{ inputs.version }}.csv diff --git a/.github/actions/get-token/action.yml b/.github/actions/get-token/action.yml index 51b0a3f0..eecc9169 100644 --- a/.github/actions/get-token/action.yml +++ b/.github/actions/get-token/action.yml @@ -23,7 +23,7 @@ runs: steps: - name: Get OIDC token id: oidc-token - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const token = await core.getIDToken('api://token-exchange-service'); @@ -32,7 +32,7 @@ runs: - name: Exchange OIDC token id: access-token - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: OIDC_TOKEN: ${{ steps.oidc-token.outputs.token }} TOKEN_EXCHANGE_URL: ${{ inputs.token-exchange-url }} diff --git a/.github/actions/merge-approved-pr/action.yml b/.github/actions/merge-approved-pr/action.yml index 8c6dea68..0f8c8590 100644 --- a/.github/actions/merge-approved-pr/action.yml +++ b/.github/actions/merge-approved-pr/action.yml @@ -60,7 +60,7 @@ runs: # Fetch PR metadata (head and base branches) using the GitHub API - name: Get PR Details - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: PR_NUMBER: ${{ inputs.pr-number }} with: @@ -97,7 +97,7 @@ runs: # Check if the PR has the required approval status - name: Verify Approval if: steps.verify-branches.outputs.should_skip != 'true' - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: PR_NUMBER: ${{ inputs.pr-number }} with: @@ -164,7 +164,7 @@ runs: # - the version change is a valid semver bump - name: Verify a version bump if: ${{ steps.verify-branches.outputs.should_skip != 'true' && inputs.verify-version-bump == 'true' }} - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: PR_NUMBER: ${{ inputs.pr-number }} with: @@ -250,7 +250,7 @@ runs: # Execute the merge if all checks pass - name: Merge PR if: steps.verify-branches.outputs.should_skip != 'true' - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: PR_NUMBER: ${{ inputs.pr-number }} MERGE_METHOD: ${{ inputs.merge-method }} diff --git a/.github/actions/merge-previous-releases/action.yml b/.github/actions/merge-previous-releases/action.yml index c87eca2b..58d9e757 100644 --- a/.github/actions/merge-previous-releases/action.yml +++ b/.github/actions/merge-previous-releases/action.yml @@ -21,14 +21,14 @@ runs: using: composite steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: ref: ${{ inputs.new-release-branch }} fetch-depth: 0 token: ${{ inputs.github-token }} - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} diff --git a/.github/actions/playwright-test-health-report/action.yml b/.github/actions/playwright-test-health-report/action.yml index 6318f1f8..c3b07c27 100644 --- a/.github/actions/playwright-test-health-report/action.yml +++ b/.github/actions/playwright-test-health-report/action.yml @@ -71,12 +71,12 @@ inputs: runs: using: composite steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} path: ./github-tools - - uses: actions/setup-node@v6 + - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version-file: ./github-tools/.nvmrc cache: yarn diff --git a/.github/actions/post-gh-rca/action.yml b/.github/actions/post-gh-rca/action.yml index 75e9d25c..d01d559f 100644 --- a/.github/actions/post-gh-rca/action.yml +++ b/.github/actions/post-gh-rca/action.yml @@ -40,7 +40,7 @@ runs: using: composite steps: - name: Post RCA Form Link - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: GOOGLE_FORM_BASE_URL: ${{ inputs.google-form-base-url }} ISSUE_LABELS: ${{ inputs.issue-labels }} diff --git a/.github/actions/post-merge-validation/action.yml b/.github/actions/post-merge-validation/action.yml index 59b40724..3d04d2f0 100644 --- a/.github/actions/post-merge-validation/action.yml +++ b/.github/actions/post-merge-validation/action.yml @@ -35,14 +35,14 @@ runs: using: composite steps: - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} path: ./github-tools - name: Set up Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version-file: ./github-tools/.nvmrc cache-dependency-path: ./github-tools/yarn.lock diff --git a/.github/actions/pr-line-check/action.yml b/.github/actions/pr-line-check/action.yml index d5c0af06..056d12b3 100644 --- a/.github/actions/pr-line-check/action.yml +++ b/.github/actions/pr-line-check/action.yml @@ -34,7 +34,7 @@ runs: # checkout, base-branch resolution or history fetching is needed, and a # webhook payload that lags a base retarget cannot skew the count. - name: Count changed lines and apply size label - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: IGNORE_PATTERNS: ${{ inputs.ignore-patterns }} MAX_LINES: ${{ inputs.max-lines }} diff --git a/.github/actions/publish-slack-release-testing-status/action.yml b/.github/actions/publish-slack-release-testing-status/action.yml index a5fa3cd5..74f48fa0 100644 --- a/.github/actions/publish-slack-release-testing-status/action.yml +++ b/.github/actions/publish-slack-release-testing-status/action.yml @@ -34,14 +34,14 @@ runs: using: composite steps: - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} path: ./github-tools - name: Set up Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version-file: ./github-tools/.nvmrc cache-dependency-path: ./github-tools/yarn.lock diff --git a/.github/actions/release-branch-sync/action.yml b/.github/actions/release-branch-sync/action.yml index 41a6f523..2b7e79ce 100644 --- a/.github/actions/release-branch-sync/action.yml +++ b/.github/actions/release-branch-sync/action.yml @@ -21,13 +21,13 @@ runs: using: composite steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: fetch-depth: 0 token: ${{ inputs.github-token }} - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} diff --git a/.github/actions/remove-rca-needed-label-sheets/action.yml b/.github/actions/remove-rca-needed-label-sheets/action.yml index 6bddd60b..a488d27e 100644 --- a/.github/actions/remove-rca-needed-label-sheets/action.yml +++ b/.github/actions/remove-rca-needed-label-sheets/action.yml @@ -32,19 +32,19 @@ runs: using: composite steps: - name: Checkout consuming repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: token: ${{ inputs.github-token }} - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} path: ./github-tools - name: Setup Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: '20' diff --git a/.github/actions/setup-e2e-env/action.yml b/.github/actions/setup-e2e-env/action.yml index 03fd2976..da1eebab 100644 --- a/.github/actions/setup-e2e-env/action.yml +++ b/.github/actions/setup-e2e-env/action.yml @@ -188,7 +188,7 @@ runs: ## Node.js & JavaScript Dependencies Setup ## - name: Setup Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: ${{ inputs.node-version }} @@ -212,7 +212,7 @@ runs: command: ${{ steps.get-corepack-command.outputs.COREPACK_COMMAND }} - name: Restore Yarn cache - uses: actions/cache@v5 + uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 with: path: | node_modules @@ -268,7 +268,7 @@ runs: # Restore cached Ruby gems - name: Restore Bundler cache if: ${{ inputs.platform == 'ios' }} - uses: actions/cache@v5 + uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 with: path: ios/vendor/bundle key: ${{ inputs.cache-prefix }}-bundler-${{ inputs.platform }}-${{ runner.os }}-${{ hashFiles('ios/Gemfile.lock') }} @@ -330,7 +330,7 @@ runs: - name: Restore CocoaPods specs cache if: ${{ inputs.platform == 'ios' }} id: cocoapods-specs-cache - uses: actions/cache@v5 + uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 with: path: ~/.cocoapods/repos key: ${{ runner.os }}-cocoapods-specs-${{ hashFiles('ios/Podfile.lock') }} diff --git a/.github/actions/stable-sync/action.yml b/.github/actions/stable-sync/action.yml index 76c73178..6e1a8747 100644 --- a/.github/actions/stable-sync/action.yml +++ b/.github/actions/stable-sync/action.yml @@ -28,13 +28,13 @@ inputs: runs: using: composite steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: fetch-depth: 0 token: ${{ inputs.github-token }} - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} @@ -42,13 +42,13 @@ runs: - name: Setup Node.js Mobile if: ${{ inputs.repo-type == 'mobile' }} - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: '18' - name: Setup Node.js Extension if: ${{ inputs.repo-type == 'extension' }} - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: '22.15' @@ -64,7 +64,7 @@ runs: - name: Check if PR exists id: check-pr - uses: actions/github-script@v9 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const { data: prs } = await github.rest.pulls.list({ diff --git a/.github/actions/stale-issue-pr/action.yml b/.github/actions/stale-issue-pr/action.yml index 6e8d38e3..21ef1d91 100644 --- a/.github/actions/stale-issue-pr/action.yml +++ b/.github/actions/stale-issue-pr/action.yml @@ -62,7 +62,7 @@ inputs: runs: using: composite steps: - - uses: actions/stale@v10 + - uses: actions/stale@1e223db275d687790206a7acac4d1a11bd6fe629 # v10.4.0 with: stale-issue-message: ${{ inputs.stale-issue-message }} close-issue-message: ${{ inputs.close-issue-message }} diff --git a/.github/actions/update-release-changelog/action.yml b/.github/actions/update-release-changelog/action.yml index 0b618be3..05894860 100644 --- a/.github/actions/update-release-changelog/action.yml +++ b/.github/actions/update-release-changelog/action.yml @@ -33,7 +33,7 @@ runs: steps: # Step 1: Checkout invoking repository (metamask-mobile | metamask-extension) - name: Checkout invoking repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: fetch-depth: 0 ref: ${{ inputs.release-branch }} @@ -41,7 +41,7 @@ runs: # Step 2: Checkout github-tools repository - name: Checkout GitHub tools repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: repository: ${{ inputs.github-tools-repository }} ref: ${{ inputs.github-tools-ref }} @@ -49,7 +49,7 @@ runs: # Step 3: Setup environment - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true diff --git a/.github/workflows/build-lint-test.yml b/.github/workflows/build-lint-test.yml index 9932c213..889e0e87 100644 --- a/.github/workflows/build-lint-test.yml +++ b/.github/workflows/build-lint-test.yml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false @@ -32,7 +32,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false diff --git a/.github/workflows/create-pr-feature-flag-registry-drift.yml b/.github/workflows/create-pr-feature-flag-registry-drift.yml index 855e8c1d..a577003e 100644 --- a/.github/workflows/create-pr-feature-flag-registry-drift.yml +++ b/.github/workflows/create-pr-feature-flag-registry-drift.yml @@ -57,18 +57,18 @@ jobs: pull-requests: write steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: token: ${{ secrets.github-token }} - name: Download registry artifact - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: ${{ inputs.registry-artifact-name }} path: ${{ inputs.registry-artifact-name }} - name: Download report artifact - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: ${{ inputs.report-artifact-name }} path: ${{ inputs.report-artifact-name }} diff --git a/.github/workflows/create-release-pr.yml b/.github/workflows/create-release-pr.yml index 9be4207c..48efd8f9 100644 --- a/.github/workflows/create-release-pr.yml +++ b/.github/workflows/create-release-pr.yml @@ -22,7 +22,7 @@ jobs: pull-requests: write steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true @@ -34,7 +34,7 @@ jobs: # branch for all git operations and the release PR. ref: ${{ github.event.inputs.base-branch }} - - uses: MetaMask/action-create-release-pr@v4 + - uses: MetaMask/action-create-release-pr@268f95dd4099efbf661dd8ad7a979e7c8cc61ff9 # v4.0.0 with: release-type: ${{ github.event.inputs.release-type }} release-version: ${{ github.event.inputs.release-version }} diff --git a/.github/workflows/lint-workflows.yml b/.github/workflows/lint-workflows.yml index 4e483906..a03b168d 100644 --- a/.github/workflows/lint-workflows.yml +++ b/.github/workflows/lint-workflows.yml @@ -9,7 +9,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Download actionlint id: download-actionlint diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 3da0cf3e..402b3df7 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -54,7 +54,7 @@ jobs: IS_RELEASE: ${{ steps.is-release.outputs.IS_RELEASE }} runs-on: ubuntu-latest steps: - - uses: MetaMask/action-is-release@v2 + - uses: MetaMask/action-is-release@3cd51b98fa98d1347d06f5961299b0172ee31ae8 # v2.3.0 id: is-release publish-release: diff --git a/.github/workflows/merge-approved-pr.yml b/.github/workflows/merge-approved-pr.yml index d9062577..1b7be9eb 100644 --- a/.github/workflows/merge-approved-pr.yml +++ b/.github/workflows/merge-approved-pr.yml @@ -38,7 +38,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Merge approved PR - uses: MetaMask/github-tools/.github/actions/merge-approved-pr@v1 + uses: MetaMask/github-tools/.github/actions/merge-approved-pr@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: pr-number: ${{ inputs.pr-number }} required-base-branch: ${{ inputs.required-base-branch }} diff --git a/.github/workflows/post-relay-subsidy-balance.yml b/.github/workflows/post-relay-subsidy-balance.yml index 164dfaf6..f03998ad 100644 --- a/.github/workflows/post-relay-subsidy-balance.yml +++ b/.github/workflows/post-relay-subsidy-balance.yml @@ -12,10 +12,10 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Setup Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version-file: .nvmrc diff --git a/.github/workflows/publish-preview.yml b/.github/workflows/publish-preview.yml index caf9b03d..0c3fbaa0 100644 --- a/.github/workflows/publish-preview.yml +++ b/.github/workflows/publish-preview.yml @@ -62,7 +62,7 @@ jobs: outputs: IS_FORK: ${{ steps.is-fork.outputs.IS_FORK }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Determine whether this PR is from a fork id: is-fork run: echo "IS_FORK=$(gh pr view --json isCrossRepository --jq '.isCrossRepository' "${PR_NUMBER}" )" >> "$GITHUB_OUTPUT" @@ -91,7 +91,7 @@ jobs: needs: react-to-comment runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Check out pull request run: gh pr checkout "${PR_NUMBER}" @@ -100,7 +100,7 @@ jobs: PR_NUMBER: ${{ github.event.issue.number }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true @@ -189,7 +189,7 @@ jobs: - name: Upload build artifacts (monorepo) if: ${{ inputs.is-monorepo }} - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: preview-build-artifacts include-hidden-files: true @@ -205,7 +205,7 @@ jobs: - name: Upload build artifacts (polyrepo) if: ${{ !inputs.is-monorepo }} - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: preview-build-artifacts include-hidden-files: true @@ -225,12 +225,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true - name: Restore build artifacts - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: preview-build-artifacts diff --git a/.github/workflows/publish-release.yml b/.github/workflows/publish-release.yml index faf9ff64..71ec8eb2 100644 --- a/.github/workflows/publish-release.yml +++ b/.github/workflows/publish-release.yml @@ -27,7 +27,7 @@ jobs: name: Announce release runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - id: name-hash name: Get Slack name and hash @@ -75,7 +75,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: # This is to guarantee that the most recent tag is fetched, which we # need for updating the shorthand major version tag. @@ -91,7 +91,7 @@ jobs: contents: write - name: Publish release - uses: MetaMask/action-publish-release@v3 + uses: MetaMask/action-publish-release@f01f1be110d60fb07d86c880ce3d6bdb353524d3 # v3.3.1 id: publish-release env: GITHUB_TOKEN: ${{ steps.get-token.outputs.token }} diff --git a/.github/workflows/stable-sync.yml b/.github/workflows/stable-sync.yml index b848dadd..b06946ff 100644 --- a/.github/workflows/stable-sync.yml +++ b/.github/workflows/stable-sync.yml @@ -26,7 +26,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Stable sync uses: ./.github/actions/stable-sync diff --git a/.github/workflows/test-add-team-label.yml b/.github/workflows/test-add-team-label.yml index c9db41bd..02ea6a28 100644 --- a/.github/workflows/test-add-team-label.yml +++ b/.github/workflows/test-add-team-label.yml @@ -12,7 +12,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Test if: ${{ github.event_name == 'pull_request' }} diff --git a/.github/workflows/test-get-release-timelines.yml b/.github/workflows/test-get-release-timelines.yml index c1def4ac..3d8eab44 100644 --- a/.github/workflows/test-get-release-timelines.yml +++ b/.github/workflows/test-get-release-timelines.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Add team label uses: ./.github/actions/get-release-timelines diff --git a/.github/workflows/upload-yarn-binary.yml b/.github/workflows/upload-yarn-binary.yml index 561dc661..4c496451 100644 --- a/.github/workflows/upload-yarn-binary.yml +++ b/.github/workflows/upload-yarn-binary.yml @@ -22,7 +22,7 @@ jobs: download_url: ${{ steps.output-url.outputs.download_url }} steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - name: Download yarn.js binary run: |